QEHSQEHS

Contract

Data Processing Addendum

Controller–processor terms for customers who process personal data in their tenants. Incorporates the EU Standard Contractual Clauses and UK IDTA.

Version
1.0
Effective
2026-04-15
Slug
/legal/dpa

Roles

Customer is data controller (or processor acting for its own controller). QEHS is data processor for customer data, and sub-processor for any onward processors customer engages.

Processing instructions

QEHS processes customer data only on documented instructions: (a) to provide the service, (b) to comply with law, or (c) as expressly authorised in writing.

Sub-processors

Listed at qehsethos.com/trust/subprocessors. 30-day prior notice of changes; customer may object on reasonable data-protection grounds.

International transfers

Transfers from the EEA, UK, or Switzerland rely on the EU SCCs (2021/914) and UK IDTA as appropriate. Supplementary measures documented in the Transfer Impact Assessment available on request.

Security & audits

Technical and organisational measures are described in Annex II and the Trust Center. Customer may audit once per year with reasonable notice, or rely on SOC 2 Type 2 / ISO 27001 reports.

Breach notification

QEHS notifies customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting customer data.

Version history

  • Version 1.0Initial publication.
    Effective 2026-04-15

Questions? Email anil@heftyinnovations.com or return to the legal index.